We performed a comparison between Qualys VMDR and Rapid7 Metasploit based on real PeerSpot user reviews.
Find out in this report how the two Risk-Based Vulnerability Management solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI."It is very easy to use and there are lots of options. We can usually easily go through it and all of the things we want to configure, and we can configure everything to our specifications very easily."
"Qualys VM's most valuable feature is automatic detection."
"This is one of the best products I have worked with so far. I like the power of Qualys, and it's a better solution because you can scan a compact file, a BIT file, or batch files. The product already knows what's happening inside, and you don't need to expand the package. Tenable will do the same thing, but you need to have a package issuance claim. With Qualys, we can immediately understand the file, even a compact file. If there's some kind of discovery or incident, you will know what happened in the environment."
"The most valuable feature is the connection of threat intelligence information with identified vulnerabilities, which means you can prioritize vulnerabilities according to actual attacks."
"The process of defining and discovering scans is organized efficiently."
"The biggest benefit is from a security operations perspective, where we are able to drive our security posture upwards by remediating any discovered vulnerabilities."
"Provides great functionality."
"The most valuable feature is automation."
"Technical support has been helpful and responsive."
"The reporting on the solution is good."
"Rapid7 Metasploit is a useful product."
"The solution is open source and has many small targetted penetration tests that have been written by many people that are useful. You can choose different subjects for the test, such as Oracle databases or Apache servers."
"I don't have any other tools like it, and I always use it when I'm doing a pen test. Metasploit is a great solution for penetration testing,"
"The Search Engineering feature is good."
"It is scalable. It's in line with our needs."
"The option to generate phishing emails has proven to be very valuable in understanding the behavior of users."
"When you want to cover yourself for scalability, you will be charged for the number you place on the scan itself."
"Make some minimal dashboard improvements."
"It is a struggle to be able to pull our report and to be able to do onboarding using automated tools."
"Finding things in management can be quite difficult."
"If anything, I would like to see the user interface modernized a bit more."
"What we have found is that the solution is not closely tied with the patch management. It is okay with newer ones, like Windows 10 machines; it gives the correct patch. But for Windows 7 or Windows Server 2008, it does not give us the correct patch so we have to manually identify the patches. This is a major problem."
"It would be nice to have an all-in-one solution that was automated and could handle the scanning and reports as well as the patching and updating."
"Qualys VM could improve by having more skilled support personnel."
"The initial setup was a bit "tweaky" for the open-source version."
"It is necessary to add some training materials and a tutorial for beginners."
"The solution is not very scalable, it does not provide any automation to be able to scale it."
"The solution should improve the responsiveness of its live technical support."
"There are numerous outdated exploits in their database that should be updated."
"I think areas with shortcomings that need improvement are more integration and automation."
"Rapid7 Metasploit could be made easier for new users to learn."
"The solution is not user-friendly and has room for improvement."
Qualys VMDR is ranked 3rd in Risk-Based Vulnerability Management with 77 reviews while Rapid7 Metasploit is ranked 11th in Vulnerability Management with 18 reviews. Qualys VMDR is rated 8.2, while Rapid7 Metasploit is rated 7.6. The top reviewer of Qualys VMDR writes "Good visibility but expensive and needs better support". On the other hand, the top reviewer of Rapid7 Metasploit writes "Helps find vulnerabilities in a system to determine whether the system needs to be upgraded". Qualys VMDR is most compared with Tenable Nessus, Tenable Security Center, Rapid7 InsightVM, Microsoft Defender Vulnerability Management and Tenable Vulnerability Management, whereas Rapid7 Metasploit is most compared with Tenable Nessus, Pentera, Acunetix, Rapid7 InsightVM and PortSwigger Burp Suite Enterprise Edition. See our Qualys VMDR vs. Rapid7 Metasploit report.
We monitor all Risk-Based Vulnerability Management reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.